Felling Insecure? You are not alone!
Today I received another letter from a reputable company that warned my that their systems had been compromised, and that my data had been involved. I've received at least 4 of these in the last several months, as I'm sure you have too.
The letters all follow a similar pattern, and include statements like: "we have no evidence that your data has been used" and "you can enroll in credit monitoring..."
Credit monitoring may be useful. I personally find the level of notifications silly, when for instance they tell me a credit card amount went up. That's just too granular. As far as protections go, the credit freeze option is really the best. That keeps others from obtaining new credit cards or loans.
But what's the deal with the number of companies with breaches? These used to be far less frequent. Are there more/better hackers? Are hacking tools just better than the tools used to defend? Or are companies just not doing what we think they should be?
The answer is Yes to all. Hackers have been in an arms race working diligently to compromise information systems since the first ones went main stream. Sometimes it's a person looking for fast money, sometimes its a nation-state, or a team of hackers funded and sponsored by a nation. With protection, and a place to work, these hacking operations can study, poke, learn, and increase the likelihood of getting into a network and stealing data - without being discovered for very long periods of time. ATT sent me a letter last month about a hacking incident that they think occurred in "2019 or earlier."
And yes, software tools for snooping, phishing, and compromising networks are better today than yesterday. BUT, so are the protections - when implemented.
Which gets us to the last point: are companies doing what they need to be doing? Today there are no laws (to my knowledge) that say that companies have to spend money or hire people dedicated to securing customer data. Many companies put nice words on their websites claiming that security is of great importance. But what are they really doing?
Comprehensive information systems security involves numerous things like perimeter defense, encryption, education, log monitoring, backups, and many other aspects. And most of this stuff is somewhat complicated, and users find it annoying. Admit it, what did you think when your laptop made you change your password???
So when choosing a partner, a vendor, or a service, I recommend looking into the company's security profile. Here are a few things to check:
Is all data transmitted over encrypted channels (HTTPS, TLS)?
Is data encrypted at rest? (This means it is stored with encryption. IF companies do this, then even when the data is stolen it will not be usable!!!)
Is there proactive system monitoring?
Is there a CISO on board? (Chief Information Security Officer)
Are regular updates made? (When I worked in the CRM market, we sold to banks who were notoriously using 5-8 year old technology. The older stuff is no where near as secure as the new.)
Unfortunately in this current climate of radical cost cutting to support higher profits, the security mechanisms look like juicy targets. If one cancels the updates to the network OS, who knows? It'll save a few bucks that go straight to profit.
At least that is true until the next breach, when they now send out the letters to customers.


Comments